CVE-2018-12526
CRITICALTelesquare SDT-CS3B1/SDT-CW3B1 <1.2.0 - Info Disclosure
Title source: llmDescription
Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=27284
Third Party Advisory x_refsource_misc
https://www.fortiguard.com/zeroday/FG-VD-18-106
Scores
CVSS v3
9.8
EPSS
0.0230
EPSS Percentile
81.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (2)
telesquare/sdt-cs3b1_firmware
< 1.2.0
telesquare/sdt-cw3b1_firmware
< 1.2.0
Published
Jun 21, 2018
Tracked Since
Feb 18, 2026